Impact
This issue is a typical DOM‑based cross‑site scripting flaw caused by improper neutralization of input during page generation. An attacker can inject malicious scripts that run in the victim’s browser, potentially allowing code execution, defacement, or credential theft. The vulnerability is limited to the context of the WordPress site where the plugin renders user‑controlled data, so it does not grant direct server or administrative access.
Affected Systems
The vulnerable plugin is "Image Style Hover" developed by DanielRiera. All released versions up to and including 1.0.6 are affected. Any WordPress installation that has any of these versions installed is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is below 1 %, meaning few incidents are expected at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to get a victim’s browser to load the compromised plugin output, typically through a crafted URL or compromised page content. Because the attack is client‑side, it depends on user interaction but can be executed automatically if the page is visited by many users.
OpenCVE Enrichment
EUVD